Privacy Policy
1. General provisions
This Policy explains what personal data the website it-master.od.ua collects, why, on what legal basis, how long it is kept, and what rights the people it relates to have.
Data controller: individual entrepreneur (FOP) I. M. Vakar, taxpayer number (RNOKPP) 3099000015, Odesa, Ukraine.
Where to write about your data: , +38 097 94 11 371. Write here if you want to find out what data we hold about you, or to have it corrected or deleted.
This Policy follows the Law of Ukraine "On Personal Data Protection" and Regulation (EU) 2016/679 (GDPR) — the latter applies because some of our clients are individuals and companies in the European Union.
Using the website means you have read this Policy. Consent to processing, where it is required, is given separately — by a checkbox in a form or a button in the cookie banner, not by merely viewing a page.
In case of any discrepancy between language versions, the Ukrainian text prevails.
2. What data we process
2.1 Contact form (/contacts)
| Data | Required | Source |
|---|---|---|
| Name | yes | you enter it |
| Phone | no | you enter it |
| no | you enter it | |
| Message text | yes | you enter it |
| Selected service | no | you choose it |
| Interface language | — | detected automatically |
| IP address | — | technical connection data |
| User-Agent (browser, device) | — | technical connection data |
| Referring page (referrer) | — | technical connection data |
Campaign tags (utm_source, utm_medium, utm_campaign) | — | from the link you arrived by |
| Country, city, approximate coordinates | — | determined locally from the IP address |
At least one of phone or email must be filled in, otherwise we cannot reply.
About location. Country and city are determined on our own server using a local MaxMind GeoLite2 database. Your IP address is not sent to any external service for this. Accuracy is city level; this is approximate data, not your actual whereabouts. The coordinates are the nominal centre of the town, not your position.
The checkbox under the form confirms that you have read this Policy. The legal basis for processing is not the checkbox but your enquiry itself: we process the data in order to answer you and, where needed, prepare a proposal. Without the checkbox the form will not be sent.
We do not ask for consent to collect the technical data — we tell you about it. The IP address, the region derived from it, the referring page and the campaign tags are recorded on the basis of legitimate interest (Art. 6(1)(f) GDPR) — to understand where enquiries come from and to protect the public form from spam. This is stated directly under the form, before you send it.
You may object to this processing — Art. 21 GDPR. Write to : we will clear the technical fields of your enquiry and stop collecting them. The enquiry itself and our reply are not affected.
2.2 Pop-up shown when you are about to leave the site
If you interact with the window that invites you to leave feedback, we store: the event type, the reason you chose, your comment (if you wrote one), the page address, the referring page, User-Agent, IP address, language, a random session identifier and the time spent on the site. Basis — your consent, given by a checkbox in the window.
The session identifier is a random value that lives only until the tab is closed. It is not linked to any account elsewhere and does not identify you.
2.3 Website security
To protect against attacks and abuse, the following are recorded automatically: IP address, User-Agent, request address, method, country and event type (for example, a bot trap being triggered or a suspicious request being blocked).
The "page not found" error log stores the address, the referring page, User-Agent and an irreversible hash of the IP address rather than the address itself — the IP cannot be recovered from it; it only serves to tell repeated requests apart.
We do not ask for consent to this: protecting the website from attacks is our legitimate interest, and the law allows such processing without consent (Art. 6(1)(f) GDPR).
2.4 Strictly necessary data
Session data is used for the website to work: IP address, User-Agent and the technical content of the session. It is kept for two hours after the last activity. Basis — legitimate interest (Art. 6(1)(f) GDPR): keeping the website technically working.
2.5 View counter for articles and author pages
To show next to an article how many times it has been read, the website counts views. Author page views are counted the same way — that number is visible only to us, in the admin area. For this, the page sends a short request to our server after it loads.
A repeat view of the same page by the same person on the same day is not counted. To determine this, the server computes an irreversible hash of the IP address, User-Agent and page number. The hashing key changes every day, so hashes from different days cannot be linked. The hash is kept until the end of the current day and then deleted.
Only the number of views of a page per day is stored — a number, with no data about who read it. Nothing is written to your browser: no cookies, no local storage. Requests from search engine robots are not counted.
Basis — legitimate interest (Art. 6(1)(f) GDPR): understanding which materials are useful to readers. The view count is shown next to an article once it reaches at least 50.
2.6 "Share" buttons
The article share buttons (Telegram, Viber, WhatsApp, Facebook, LinkedIn, X) are ordinary links. Until you click one, none of these networks receives anything: their scripts are not loaded on the website.
When you click a button, the corresponding service or app opens and receives the article address and its title. From then on, that service's rules apply. A utm_source tag with the network name is added to the address so that we can see in our statistics where readers come from.
The "Copy link" button copies the address to your clipboard.
What we count. Pressing a button sends our server a short note: which network was chosen. The article address you share carries the tags utm_source (the network), utm_medium=share and utm_content — the type of device it was shared from: pc or mobile. When someone opens the article through such a link, we count the visit. Only daily counts are stored — article, network, device type (computer or phone, derived from the User-Agent) — with no data about who shared or visited. Repeats within a day and robot requests are filtered out the same way as in section 2.5.
Basis — legitimate interest (Art. 6(1)(f) GDPR): understanding which materials are shared and where.
2.7 Analytics — only with your consent
If you have agreed to the "analytics" category in the cookie banner, the following are loaded:
| Service | What it does | Who receives the data |
|---|---|---|
| Google Analytics 4 (via Google Tag Manager) | visit statistics, traffic sources, on-page behaviour | |
| Google Ads | measuring advertising effectiveness (if a campaign is running) | |
| Microsoft Clarity | heatmaps and session recording — mouse movements, clicks, scrolling | Microsoft |
| Ahrefs Analytics | cookieless visit statistics | Ahrefs Pte. Ltd. |
About session recording. Microsoft Clarity records your interaction with the page. Input into form fields is masked (this is Clarity's default behaviour) — the text you type is not recorded. We use these recordings solely to fix layout errors and improve usability.
If you have not agreed to analytics, none of these services is loaded at all. This is not an "anonymous mode" — no requests are made to Google, Microsoft or Ahrefs.
Basis — your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time on the page of this Policy, with the "Change cookie settings" button.
2.8 What we do not do
we do not collect data you did not knowingly provide or that is not listed above;
we do not ask for or store payment details on the website;
we do not collect special categories of data (health, political views, biometrics, etc.);
we do not make decisions about you solely by automated means;
we do not sell or pass data to third parties for their own marketing;
we do not use your enquiries to train artificial intelligence systems.
3. Why we process it
| Purpose | Data | Basis |
|---|---|---|
| Answer an enquiry, prepare a proposal | name, contacts, text, selected service | steps prior to entering into a contract, Art. 6(1)(b) |
| Notify the person responsible about a new enquiry | the same | the same |
| Understand which region and channel enquiries come from | location, UTM, referrer | legitimate interest, Art. 6(1)(f) |
| Prevent abuse of the public form | IP, User-Agent | legitimate interest, Art. 6(1)(f) |
| Improve the website and remove reasons for leaving | pop-up data | consent, Art. 6(1)(a) |
| Protect the website from attacks | security logs | legitimate interest, Art. 6(1)(f) |
| Fix broken links | 404 log with an IP hash | legitimate interest, Art. 6(1)(f) |
| Count article and author page views | daily hash of IP + User-Agent (until the end of the day), view count | legitimate interest, Art. 6(1)(f) |
| Count article shares | daily hash of IP + User-Agent (until the end of the day), counts of presses and visits by network and device type | legitimate interest, Art. 6(1)(f) |
| Keep the website working | session, CSRF protection | legitimate interest, Art. 6(1)(f) |
| Web analytics and advertising measurement | GA4, Google Ads, Clarity, Ahrefs | consent in the banner, Art. 6(1)(a) |
4. How long we keep it
| Data | Period | What happens next |
|---|---|---|
| Contact form enquiries | 36 months from receipt | deleted automatically, irreversibly |
| Pop-up events | 12 months | the same |
| Security log | 30 days (informational), 90 days (warnings), 365 days (incidents) | the same |
| 404 log | 30–180 days depending on the record type | the same |
| Session | 2 hours after the last activity | deleted |
| Hash for the view counter | until the end of the current day | deleted |
| Number of views of an article or author page per day | indefinitely | an anonymous number containing no personal data |
| Number of shares and visits per day | indefinitely | anonymous numbers containing no personal data |
| Blocked address list | until the block expires | deleted |
Deletion runs automatically every day. The periods are fixed in the website configuration, not set by hand.
Data collected by Google, Microsoft, Cloudflare and Ahrefs is kept under their own rules — see the links at the end of section 6.
Web server logs (including the IP addresses of requests) are kept by the hosting provider under its own rules.
5. Cookies and similar technologies
The banner appears on your first visit. There are two categories:
5.1 Necessary — always on
The website does not work without them; they do not require consent.
| Name | Purpose | Lifetime | Set by |
|---|---|---|---|
it-master-session | session identifier | 2 hours | the website |
XSRF-TOKEN | protection against request forgery | 2 hours | the website |
itm_consent | remembers your choice in the banner | 6 months | the website |
__cf_bm, cf_clearance | bot protection | under Cloudflare's rules | Cloudflare |
5.2 Analytics — only after consent
| Name | Purpose | Lifetime | Set by |
|---|---|---|---|
_ga, _ga_* | distinguishing visitors in GA4 | up to 2 years | |
_clck, _clsk | Clarity identifier and session | 1 year / 1 day | Microsoft |
Ahrefs Analytics works without cookies, but is likewise loaded only after consent: it still sends your IP address, the page address and the referring page to its server.
No cookies are used to remember the language (it is determined by the page address), the colour theme or the font size — the latter are stored locally in your browser and are not sent to the server.
5.3 How to change your decision
Use the "Change cookie settings" button on this page. You can also delete cookies in your browser — the banner will then appear again.
6. Who receives the data
We do not sell data. It is passed only to providers without whom the website does not work, and only to the extent needed for that.
| Recipient | What it receives | Why | Where it processes |
|---|---|---|---|
| Cloudflare, Inc. | all website traffic, IP addresses | attack protection, acceleration, "are you a robot" check | global network |
| Google LLC (Gmail SMTP) | the content of the new-enquiry notification | delivering the email to the person responsible | EU / USA |
| Google LLC (GA4, Ads, GTM) | analytics data — only with consent | statistics, advertising measurement | EU / USA |
| Microsoft Corporation (Clarity) | session recordings — only with consent | interface analytics | EU / USA |
| Ahrefs Pte. Ltd. | visit statistics — only with consent | cookieless web analytics | Singapore / EU |
| Hosting provider Hostpro | data stored on the server | hosting the website | the provider's data centre |
Data may also be provided to public authorities where the law requires it — within the scope of the request and no further.
"Are you a robot" check (Cloudflare Turnstile): the verification token is sent to Cloudflare for confirmation and is not stored on the website in any form.
The providers' own data processing rules:
Cloudflare — cloudflare.com/privacypolicy;
Google (GA4, Ads, GTM, Gmail) — policies.google.com/privacy;
Microsoft (Clarity) — privacy.microsoft.com/privacystatement;
Ahrefs — ahrefs.com/legal/privacy-policy;
Hostpro — hostpro.ua/ua/documents (in Ukrainian).
6.1 Transfers outside Ukraine and the EEA
Google, Microsoft, Cloudflare and Ahrefs may process data outside Ukraine — including in the USA and Singapore. Transfers rely on the EU Standard Contractual Clauses and on the EU–US Data Privacy Framework, in which Google, Microsoft and Cloudflare participate.
We use the standard data processing terms these providers offer their customers as part of their terms of service. For transfers to countries without a European Commission adequacy decision (including Singapore), the EU Standard Contractual Clauses apply.
7. Client data we get access to while working
This section is not about website visitors but about clients whose infrastructure we work with: servers, networks, workstations, databases, accounts.
While performing work, we may get access to information containing personal data of your employees or customers. For that information we act as a processor; you remain the controller.
We undertake to:
Process it only within the task. Access is used for the agreed work and for nothing else.
Not copy it without need. Backups, database dumps and log exports are created only when needed to do the work and are deleted after it is finished. If a copy has to be kept longer, this is agreed with you separately.
Not pass it to third parties — in full or in part — except where the law directly requires it.
Limit who has access. Only those of our specialists who need it for the specific task have access.
Return or revoke access after the work is finished, at your request.
Notify you without delay if we become aware of unauthorised access to your data.
The procedure and limits of access to your systems are set out in the Public Offer.
8. Your rights
You have the right to:
know whether your data is processed and get a copy of it;
rectify inaccurate data;
erase data (the "right to be forgotten");
restrict processing;
object to processing based on legitimate interest;
receive your data in a machine-readable format and transfer it to another controller;
withdraw consent at any time — this does not affect the lawfulness of processing before withdrawal;
lodge a complaint with a supervisory authority.
How to exercise them: write to . We reply within 30 calendar days. If a request is complex, this period may be extended; we will tell you so and give the reason.
To protect your own data, we may ask you to confirm your identity — for example, by replying from the address the enquiry came from. We do not ask for unnecessary documents.
Supervisory authorities:
Ukraine — the Ukrainian Parliament Commissioner for Human Rights;
EU — the data protection authority of your country of residence.
9. Data security
Connections to the website are encrypted (HTTPS). Only authorised persons with separated permissions have access to the administrative area. The website is protected against automated attacks, and data is stored on a server with restricted access.
No protection is absolute. If a breach occurs that threatens your rights, we will notify you and the supervisory authority within the time limits set by law.
10. Children
The website is intended for a business audience and is not aimed at persons under 16. We do not knowingly collect their data. If you become aware otherwise, write to and we will delete such data.
11. Changes to this Policy
We publish a new revision on this page with its date and number. Previous revisions are kept and provided on request — this makes it possible to establish which revision was in force on a given date.
If the changes are material — for example, a new purpose of processing or a new recipient of data appears — we will give additional notice and, where consent is required, ask for it again.